Scalable and Precise Program Analysis for Modern Software Systems
Scalable and Precise Program Analysis for Modern Software Systems
批准号:
RGPIN-2017-05070
负责人:
Ali, Karim
金额:
$1.82万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31
中文摘要
程序分析工具可以帮助检测并可能修复许多软件错误。然而,经验研究表明,在实践中,软件开发人员避免使用大多数程序分析工具,因为这些工具不能扩展到现代软件系统,报告许多误报,或者破坏开发人员的工作流程。******软件开发人员对程序分析工具的许多抱怨都是由于这些工具所做的潜在的不切实际的假设。特别是对于超大规模的软件系统,对整个程序进行分析是不可行的。此外,现代软件系统是建立在许多难以精确分析的库之上的,因为它们在应用程序代码和库代码之间表现出复杂的依赖关系。******提出的研究旨在通过两个主要的研究活动发现一个全面的解决方案,将精确的程序分析扩展到现代软件系统:(1)开发一种实用的方法来构建现有库和框架的抽象,使它们更适合于程序分析;(2)在库的开发过程中设计一种主动的方法来创建库抽象。******所提出的研究结果将对研究人员和软件开发人员都很有用。提出的部分程序分析将使研究人员能够探索超大规模框架和现代软件系统的分析。它们还可以在现实环境中更广泛地部署程序分析工具,这有助于软件开发人员在开发过程中尽早发现软件缺陷和安全漏洞。软件漏洞的早期检测将提高使用这些工具的软件开发人员的整体生产力,并帮助软件公司(如BioWare)每年节省因软件故障而损失的数十亿美元。
英文摘要
Program-analysis tools can help detect, and possibly fix, many software bugs. However, empirical research has shown that, in practice, software developers refrain from using most program-analysis tools, because the tools do not scale to modern software systems, report many false positives, or disrupt the workflow of developers.******Many of the complaints that software developers have made about program-analysis tools are due to the underlying impractical assumptions that these tools make. In particular, for ultra-large-scale software systems, it is not feasible to analyze the whole program. Additionally, modern software systems are built on top of many libraries that are hard to analyze precisely, because they exhibit complicated dependencies between the application code and the library code.******The proposed research aims at discovering a comprehensive solution to scaling precise program analysis to modern software systems through two main research activities: (1) developing a pragmatic approach to construct abstractions of existing libraries and frameworks that make them more amenable to program analysis, and (2) devising a proactive approach to create library abstractions during the development process of the library.******The findings of the proposed research will be useful for both researchers and software developers. The proposed partial-program analyses will enable researchers to explore analyses for ultra-large-scale frameworks and modern software systems. They will also enable wider deployment of program-analysis tools in real-world settings, which helps software developers detect software bugs and security vulnerabilities as early as possible in the development process. Early detection of software bugs will improve the overall productivity of software developers using these tools, and help software companies, such as BioWare, save billions of dollars that are lost due to software failures every year.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Scalable and Precise Program Analysis for Modern Software Systems
-
批准号:RGPIN-2017-05070
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2022
-
负责人:Ali, Karim
-
依托单位:
Scalable and Precise Program Analysis for Modern Software Systems
-
批准号:RGPIN-2017-05070
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.82万
-
财政年份:2021
-
负责人:Ali, Karim
-
依托单位:
Scalable and Precise Program Analysis for Modern Software Systems
-
批准号:RGPIN-2017-05070
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.82万
-
财政年份:2020
-
负责人:Ali, Karim
-
依托单位:
Scalable and Precise Program Analysis for Modern Software Systems
-
批准号:RGPIN-2017-05070
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.82万
-
财政年份:2019
-
负责人:Ali, Karim
-
依托单位:
Scalable and Precise Program Analysis for Modern Software Systems
-
批准号:RGPIN-2017-05070
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.82万
-
财政年份:2017
-
负责人:Ali, Karim
-
依托单位:
海外基金